ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿£¿£¿£¿£¿£¿£¿£¿î3.5ÍòÃÀÔª
°ä²¼¹¦·ò 2022-04-241¡¢Cisco½¨¸´ÆäUmbrella VAµÈ¶à¸ö²úÆ·ÖеÄ3¸ö·ì϶
4ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Cisco°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´Æä¶à¿î²úÆ·Öеķì϶¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬Cisco TelePresenceºÏ×÷Öն˺ÍRoomOSÈí¼þÖеĻؾø·þÎñ·ì϶£¨CVE-2022-20783£©£¬£¬£¬£¬£¬£¬£¬£¬Ô´ÓÚ²»×ãÊäÈëÑéÖ¤£»£»£»£»£»£»£»Cisco UmbrellaÐé¹¹É豸(VA)¾²Ì¬SSHÖ÷»úÃÜÔ¿Öеķì϶£¨CVE-2022-20773£© £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´¶ÔSSHÏνÓÖ´ÐÐMitM¹¥»÷²¢½Ù³ÖÖÎÀíԱʹ´¦£»£»£»£»£»£»£»ÒÔ¼°Cisco Virtualized Infrastructure ManagerÖеÄÌáȨ·ì϶£¨CVE-2022-20732£©¡£¡£¡£¡£¡£¡£¡£
https://www.cisa.gov/uscert/ncas/current-activity/2022/04/21/cisco-releases-security-updates-multiple-products-0
2¡¢T-Mobile³ÆLAPSUS$ÍÅ»ïʹÓñ»µÁÍ´´¦½Ó¼ûÆäÄÚ²¿ÏµÍ³
¾ÝýÌå4ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬T-Mobile³ÆÀÕË÷ÍÅ»ïLapsus$ÔÚ¼¸ÖÜǰʹÓñ»µÁÍ´´¦ÈëÇÖÁËÆäÍøÂ磬£¬£¬£¬£¬£¬£¬£¬²¢»ñµÃÁ˶ÔÄÚ²¿ÏµÍ³µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¹³ä˵£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ·¢ÏÖÎÊÌâºóËüÁ¢¿Ì¶Â½ØÁ˹¥»÷Õß¶ÔÆäÍøÂçµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬²¢½ûÓÃÁ˹¥»÷ÖÐʹÓõÄÍ´´¦¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝT-MobileµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬£¬Lapsus$ÔÚ¹¥»÷ÆÚ¼ä²¢Î´ÇÔÈ¡¿Í»§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËԱͨ¹ý¸ÃÍÅ»ïµÄÄÚ²¿Ì¸Ìì¼Í¼·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ËûÃǽӼûÁËT-MobileµÄÄÚ²¿¿Í»§ÕË»§ÖÎÀí¹¤¾ßAtlas£¬£¬£¬£¬£¬£¬£¬£¬ÈëÇÔìäSlackºÍBitbucketÕË»§£¬£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÕË»§ÏÂÔØÁË30000¶à¸öÔ´´úÂë´æ´¢¿â¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/04/t-mobile-admits-lapsus-hackers-gained.html
3¡¢LockBitÐû³ÆÒÑÇÔÈ¡ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃÅÔ¼420GBµÄÊý¾Ý
ýÌå4ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïLockBitÐû³Æ¹¥»÷ÁËÀïÔ¼ÈÈÄÚ¬µ±¾Ö°ì¹«ÊÒµÄϵͳ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÔ¼420 GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÀïÔ¼ÈÈÄÚ¬ÊǰÍÎ÷µÚ¶þ´ó³ÇÊУ¬£¬£¬£¬£¬£¬£¬£¬ÄÏÃÀÖ޵ĽðÈÚÖÐÐÄÖ®Ò»£¬£¬£¬£¬£¬£¬£¬£¬ÆäGDPÔÚÈ«ÇòÅÅÃûµÚ30λ¡£¡£¡£¡£¡£¡£¡£ÀïÔ¼ÈÈÄÚ¬²ÆÕþ²¿ÃŵĹÙÔ±ÔÚÉÏÖÜÎå֤ʵ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÔÚ´¦ÖÃÕë¶ÔÆäϵͳµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã¹ÙÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÍþвҪй¶´ÓSefaz-RJϵͳÖÐÇÔÈ¡µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬µ«ÕâЩÊý¾Ý½öÏ൱ÓÚÃØÊé´¦Öü´æÊý¾ÝµÄ0.05%¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/rio-de-janeiro-finance-department-hit-with-lockbit-ransomware/
4¡¢ÃÀ¹úµ±¾Öй©ÆäÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶
¾Ý4ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹úºÓɽ°²È«Êýй©ÆäHack DHS·ì϶Éͽð´òËãÒÑÔÚDHS±í²¿ÏµÍ³Öз¢ÏÖ122¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£DHSÏò³¬¹ý450Ãû×êÑÐÈËÔ±¼Î½±ÁË125600ÃÀÔª£¬£¬£¬£¬£¬£¬£¬£¬Ã¿¸ö·ì϶µÄ½«½ü¾ùÔÈΪ5000ÃÀÔª¡£¡£¡£¡£¡£¡£¡£Hack DHS´òËãÓÚ2021Äê12ÔÂÆô¶¯£¬£¬£¬£¬£¬£¬£¬£¬ËüÒªÇóºÚ¿ÍÅû¶·ì϶µÄ¾ßÌåÐÅÏ¢¡¢ÈôºÎÀûÓÃËüÒÔ¼°ÈôºÎʹÓÃËü½Ó¼ûDHSϵͳ¡£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬£¬£¬DHS½«ÔÚ48Ó×ʱÄÚÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ15Ìì»ò¸ü³¤¹¦·òÄÚ½¨¸´¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hack-dhs-bug-hunters-find-122-security-flaws-in-dhs-systems/
5¡¢ÐÂ¼ÓÆÂGeniusUÒòй¶126ÍòÓû§µÄÐÅÏ¢±»·£¿£¿£¿£¿£¿£¿£¿£¿î3.5ÍòÃÀÔª
ýÌå4ÔÂ22Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂ½ÌÓý¿Æ¼¼¹«Ë¾GeniusUй¶126ÍòÓû§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÐÂ¼ÓÆÂÓ×ÎÒÊý¾Ý±£»£»£»£»£»£»£»¤Î¯Ô±»á(PDPC)ÔÚ4ÔÂ21ÈÕ°ä²¼µÄÊéÃæ¾ö¶¨ÖаµÊ¾£¬£¬£¬£¬£¬£¬£¬£¬GeniusUδÄÜÔì¶©ºÏÀíµÄÕ½Êõ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Î»ÏàÐÅÏ¢ºÍÉϴεǼIPµØÖ·µÈÐÅÏ¢±»µÁ£¬£¬£¬£¬£¬£¬£¬£¬·£¿£¿£¿£¿£¿£¿£¿£¿î35000ÃÀÔª¡£¡£¡£¡£¡£¡£¡£GeniusUµÄÄÚ²¿µ÷²é·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñ¿ÉÄÜÊÇÆä¿ª·¢ÈËÔ±µÄÕÊ»§±»µÁµ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃËûµÄGitHubÕÊ»§ÕÒµ½Á˵Ǽʹ´¦£¬£¬£¬£¬£¬£¬£¬£¬»ñµÃÁËGeniusUÊý¾Ý¿âµÄ½Ó¼ûȨÏÞ²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£
https://www.straitstimes.com/tech/tech-news/edu-tech-firm-geniusu-fined-35000-for-data-leak-affecting-126m-users
6¡¢Mandiant°ä²¼2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨
4ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Mandiant°ä²¼ÁË2021ÄêÒѱ»ÀûÓÃ0-dayµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬£¬MandiantÔÚÈ¥Äê·¢ÏÖÁË80Æð0-dayÔÚÒ°±í±»ÀûÓõÄÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬±È2020ÄêºÍ2019ÄêµÄ×ܺͻ¹¶àÁË18Æð¡£¡£¡£¡£¡£¡£¡£2021Äê0-day¹¥»÷µÄÖØÒª³§ÉÌÊÇ΢Èí¡¢Æ»¹ûºÍ¹È¸è£¬£¬£¬£¬£¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ75%ÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£Õë¶ÔÒÆ¶¯²Ù×÷ϵͳAndroidºÍiOSµÄ0-dayÊýÁ¿Ò²³ÊÉÏÉýÇ÷Ïò£¬£¬£¬£¬£¬£¬£¬£¬´Ó2019ÄêºÍ2020ÄêµÄ²»µ½5¸öÔö³¤µ½2021ÄêµÄ17¸ö¡£¡£¡£¡£¡£¡£¡£´ó²¿ÃŹ¥»÷¹éÒòÓÚ¹ú¶ÈÖ§³ÖµÄ¼äµý»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÀûÓÃ0-dayµÄ¹¥»÷ÕßÖÐÓÐÈý·ÖÖ®Ò»³öÓÚ¾¼Ã¶¯»ú¡£¡£¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/zero-days-exploited-2021


¾©¹«Íø°²±¸11010802024551ºÅ